Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
AES-256-GCM Authenticated PBKDF2-SHA256 (310k+ Iterations) Zero Server Transmission

Zero-Knowledge Encrypted Notes & AES-256-GCM Vault

Encrypt and decrypt sensitive text, credentials, API keys, or recovery seed phrases directly inside your browser. Powered by the native Web Cryptography API with zero-knowledge architecture—no unencrypted data or keys ever touch a remote server.

Strength: Enter passphrase Estimated Entropy: 0 bits
0 chars | 0 bytes
0 bytes
AES-256-GCM
Cipher Mode
PBKDF2-SHA256
Key Derivation
16 Bytes
CSPRNG Salt
12 Bytes (96-bit)
Unique Nonce / IV
128-bit Tag
Integrity Auth
0 ms
Process Latency

Cryptographic Architecture & Mathematical Derivations

Digital Tools Shed uses an authenticated encryption pipeline combining Password-Based Key Derivation Function 2 (PBKDF2) with Galois/Counter Mode (AES-GCM). Unlike unauthenticated block modes, this architecture guarantees both mathematical confidentiality and tamper detection.

1. Key Stretching (PBKDF2-HMAC-SHA256): DK = PBKDF2(PRF = HMAC-SHA256, Password = P, Salt = S, Iterations = c, dkLen = 256 bits) Where: U_1 = PRF(P, S || INT_32_BE(i)) U_2 = PRF(P, U_1) ... U_c = PRF(P, U_{c-1}) F(P, S, c, i) = U_1 ⊕ U_2 ⊕ ... ⊕ U_c Cost: 310,000 SHA-256 passes force adversary GPU clusters to compute 620,000 compression operations per password guess. 2. Authenticated Encryption (AES-GCM-256): Ciphertext: C = AES-CTR(K, IV, Plaintext) GHASH Hash: H = AES_K(0^128) Auth Tag: T = GHASH_H(A || C) ⊕ AES_K(J_0) Where: - IV is 96 bits (12 bytes) fresh CSPRNG randomness - T is 128 bits (16 bytes) verifying that not a single bit of ciphertext was altered - Verification fails instantly if a bit flip occurs (Forging probability = 2^-128 ≈ 2.94 × 10^-39)

5 Fatal Traps in In-Browser Web Encryption

Trap 1: Nonce/IV Reuse in AES-GCM (Catastrophic Key Recovery) In Galois/Counter Mode, using the same 96-bit Initialization Vector (IV) more than once under the same AES key completely destroys message authenticity. An attacker observing two ciphertexts encrypted with the same IV can XOR the ciphertexts to recover the XOR of the plaintexts, and can mathematically solve the GHASH polynomial to extract the authentication subkey H, enabling undetectable message forgery. Digital Tools Shed generates a fresh 12-byte CSPRNG nonce on every single encryption call.
Trap 2: Insufficient PBKDF2 Iteration Counts (ASIC Brute-Force Vulnerability) Using outdated PBKDF2 iteration counts (such as 1,000 or 10,000 rounds) leaves encrypted notes defenseless against modern password-cracking hardware. A modest rig of eight NVIDIA RTX 4090 GPUs can compute over 50 billion SHA-256 hashes per second. At 10,000 iterations, a 6-character password is shattered in under 3 minutes. Our vault enforces 310,000 iterations (OWASP recommendation) or 600,000 iterations, multiplying the attacker's compute cost by up to 60×.
Trap 3: In-Browser Plaintext Memory Snooping & DOM Heap Retention While 256-bit AES-GCM is mathematically unbreakable by brute force, JavaScript strings in the browser DOM and V8 garbage collector heap persist in memory until reclaimed. Rogue browser extensions with permission to read web pages, compromised analytics tags, or OS swap files can inspect active DOM values. Always close browser tabs after handling sensitive notes and ensure zero unvetted extensions run in your environment.
Trap 4: Malleability of Unauthenticated Cipher Modes (CBC/CTR Padding Oracles) Legacy tools that use AES-CBC or AES-CTR without an HMAC authentication tag provide confidentiality but zero integrity. In CBC mode, attackers exploit error response timing (padding oracle attacks) to decrypt ciphertext byte by byte without knowing the key. In CTR mode, bit-flipping attacks allow adversaries to modify specific characters in the decrypted note. AES-GCM eliminates both vulnerabilities via its embedded 128-bit GHASH authentication tag.
Trap 5: Unsalted Key Derivation & Rainbow Table Precomputation Deriving an encryption key directly from SHA-256 of the password without a cryptographically random salt allows attackers to execute batch attacks using precomputed rainbow tables. Two users with the same passphrase would also produce identical keys. Our engine generates a unique 16-byte (128-bit) CSPRNG salt for every encryption cycle, ensuring that even identical passphrases generate completely unique 256-bit AES keys.

Frequently Asked Questions

Is my passphrase or note ever sent to your servers?
No, absolutely never. This tool runs 100% locally inside your web browser using the native Web Cryptography API (window.crypto.subtle). Encryption and decryption keys are derived in volatile browser RAM and wiped immediately. No data packets are ever transmitted over the network.
What encryption algorithm and key derivation function are used?
The tool uses authenticated 256-bit AES-GCM (Advanced Encryption Standard in Galois/Counter Mode) with an intrinsic 128-bit authentication tag. Keys are stretched from your master passphrase using PBKDF2 with HMAC-SHA-256, a unique 16-byte random salt, and up to 600,000 iterations adhering to OWASP recommendations.
What happens if I lose or forget my passphrase?
Because this tool adheres to strict zero-knowledge cryptographic principles, there are no backdoors, recovery keys, or master resets. If you lose your passphrase, the ciphertext payload is mathematically unrecoverable and cannot be brute-forced within any realistic timeframe.
Why is AES-GCM safer than older modes like AES-CBC?
AES-CBC provides confidentiality but lacks integrity verification, leaving it vulnerable to padding oracle attacks and ciphertext bit-flipping. AES-GCM provides both confidentiality and cryptographic integrity verification in a single pass using a Galois field multiplier (GHASH).
What is inside the exported encrypted payload?
The payload contains a 4-byte format header (DTS1), a 4-byte big-endian iteration count, a 16-byte cryptographically secure random salt, a 12-byte random initialization vector (IV/nonce), and the AES-256-GCM ciphertext combined with the 16-byte authentication tag, encoded as Base64 or Hex.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement